From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mail-wr0-f195.google.com ([209.85.128.195]:37974 "EHLO mail-wr0-f195.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1752121AbeCCRBs (ORCPT ); Sat, 3 Mar 2018 12:01:48 -0500 Received: by mail-wr0-f195.google.com with SMTP id n7so13095382wrn.5 for ; Sat, 03 Mar 2018 09:01:48 -0800 (PST) From: Jean-Philippe Brucker To: stephen@networkplumber.org Cc: netdev@vger.kernel.org Subject: [PATCH iproute2] ss: fix NULL dereference when rendering without header Date: Sat, 3 Mar 2018 16:59:44 +0000 Message-Id: <20180303165944.28102-1-jphilippe.brucker@gmail.com> Sender: netdev-owner@vger.kernel.org List-ID: When ss is invoked with the no-header flag, if the query doesn't return any result, render() is called with 'buffer' uninitialized. This currently leads to a segfault. Ensure that buffer is initialized before rendering. The bug can be triggered with: ss -H sport = 100000 Signed-off-by: Jean-Philippe Brucker --- misc/ss.c | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/misc/ss.c b/misc/ss.c index e047f9c0..e087bef7 100644 --- a/misc/ss.c +++ b/misc/ss.c @@ -1197,10 +1197,15 @@ newline: /* Render buffered output with spacing and delimiters, then free up buffers */ static void render(int screen_width) { - struct buf_token *token = (struct buf_token *)buffer.head->data; + struct buf_token *token; int printed, line_started = 0; struct column *f; + if (!buffer.head) + return; + + token = (struct buf_token *)buffer.head->data; + /* Ensure end alignment of last token, it wasn't necessarily flushed */ buffer.tail->end += buffer.cur->len % 2; -- 2.16.2